Skip to content

Microsoft.Authorization/locks/delete

Azure

Microsoft.Authorization/locks/delete

service: Azure - Authorization
tactics:
techniques:

Event

Removes a specific CanNotDelete or ReadOnly lock. Locks govern control-plane operations, not all data-plane activity. Parent locks can still apply after a child lock is removed. Lock deletion does not itself delete a protected resource or grant permission to do so.

Security Context

Unauthorized removal may prepare destructive activity (contextual T1485). Approved maintenance also removes locks. Risk depends on the actual lock level, inherited locks, permissions, and subsequent operations; the lock’s name is not proof of its settings.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Authorization/locks/delete. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
resourceIdDeleted lock and its scope.
caller, statusActor and outcome; recover the previous lock level separately.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Recover the lock’s previous level and maintenance approval.
  3. Check inherited locks, resource policies, and the actor’s effective permissions after removal.
  4. Correlate resource changes/deletions and actual impact; this record alone is not data destruction.

Sample Event

Synthetic scenario. The sample deletes a resource-group lock named prod-cannotdelete. Its prior level and remaining protections are not present in the event.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Authorization/locks/delete",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Authorization/locks/prod-cannotdelete"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud"
},
"correlationId": "90000000-0000-4000-8000-000001111000",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000001111001",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T20:14:08.7172948Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000001111010",
"operationName": {
"value": "Microsoft.Authorization/locks/delete",
"localizedValue": "Delete management lock"
},
"resourceGroupName": "rg-fantasticlogs-prod",
"resourceProviderName": {
"value": "Microsoft.Authorization",
"localizedValue": "Microsoft.Authorization"
},
"resourceType": {
"value": "Microsoft.Authorization/locks",
"localizedValue": "Microsoft.Authorization/locks"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Authorization/locks/prod-cannotdelete",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T20:14:09.2018844Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Authorization/locks/prod-cannotdelete",
"message": "Microsoft.Authorization/locks/delete",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000001111011",
"clientIpAddress": "203.0.113.66",
"method": "DELETE",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Authorization/locks/prod-cannotdelete?api-version=2020-05-01"
},
"identity": null
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.